[Oisf-users] address-group syntax

Michael Stone mstone at mathom.us
Mon Feb 6 16:27:14 UTC 2017

Is the syntax for address-groups (e.g., HOME_NET) fully described 
anywhere?  There are config file examples that suggest some syntax, but 
there's also a todo note in detect-engine-address.c that suggests that 
certain forms won't work properly (e.g., I think, setting HOME_NET to 
[!] and EXTERNAL_NET to !HOME_NET / ![!] ?) It's 
certainly possible to experiment, but it would be nice to know what is 
supposed to work and what isn't.

Mike Stone

